Maintain a formal information system security program, including systems security plans, cyber security policies, security control assessments, contingency plans, configuration management plans, incident response plans, plan of actions and milestones, risk management plans, vulnerability scanning, and/or vulnerability management plans. Ensures cybersecurity-related events or configuration changes that impact AF IT authorization or adversely impact the security posture are formally reported to the Authorizing Official (AO) and other affected parties, such as Information Owners (IOs) and stewards and AOs of interconnected IT.